Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention.
We have discovered 390 live websites that are affected by CVE-2025-43960.
| Product | |
| Category | Database Managers |
| Vulnerable Domains | 390 live websites (82% of Adminer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 24 versions ( 67% of all versions) |
| 116 websites | |
| 91 websites | |
| 59 websites | |
| 20 websites | |
| 17 websites | |
| 10 websites | |
| 10 websites | |
| 8 websites | |
| 7 websites | |
| 6 websites |
| .com | 137 websites |
| .cz | 85 websites |
| .ru | 17 websites |
| .net | 16 websites |
| .org | 14 websites |
| .de | 13 websites |
| .eu | 10 websites |
| .nl | 7 websites |
| .io | 6 websites |
| .fr | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.********.com | **,*** | ||
| ******.***.pl | ***,*** | ||
| *******.pl | ***,*** | ||
| ****.*****.com | ***,*** | ||
| *********.com | ***,*** | ||
| **************.ru | ***,*** | ||
| ***.*********.com | ***,*** | ||
| ***********.************.com | ***,*** | ||
| ******.*************.cz | ***,*** | ||
| *******.***.cn | ***,*** |